# Fortinet FortiOS SSL-VPN RCE flaw exploited

Published: 2022-12-13 · Severity: critical
Canonical: https://vorant.io/reports/5c74bd9b-887f-5451-a94c-823a7980d8fe/fortinet-fortios-ssl-vpn-rce-flaw-exploited

> A heap-based buffer overflow in FortiOS SSL-VPN lets unauthenticated attackers run arbitrary code, and active exploitation has been confirmed.

IPA issued an alert regarding a heap-based buffer overflow vulnerability in Fortinet's FortiOS SSL-VPN, a widely used remote access product. The flaw allows an unauthenticated remote attacker to send specially crafted requests to the SSL-VPN interface, potentially resulting in arbitrary code or command execution on the affected device.

The advisory confirms that exploitation of this vulnerability has already been observed in the wild, and warns that damage could expand if organizations do not patch promptly. Fortinet has released updated versions addressing the issue, along with interim workarounds and guidance for checking whether systems have already been compromised. IPA urges affected organizations to apply the vendor-provided update immediately and to review Fortinet's guidance for indicators of prior exploitation.

Given the pre-authentication nature of the vulnerability, its presence in a widely deployed VPN gateway product, and confirmed in-the-wild exploitation, this represents a significant remote access risk for organizations using FortiOS SSL-VPN.

## Mentioned in this report

- Vulnerabilities: CVE-2022-42475 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/alert20221213.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5c74bd9b-887f-5451-a94c-823a7980d8fe/fortinet-fortios-ssl-vpn-rce-flaw-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
